You do not need a 60-page security plan to be “serious” about ransomware. You need a short, shared view of what matters most when the worst day shows up.
That is exactly what NIST’s updated ransomware risk management profile is trying to give you. It is aligned to the NIST Cybersecurity Framework (CSF) 2.0, and it is written to help you choose practical outcomes that reduce downtime.
What NIST released, in plain English
In June 2026, NIST published an updated version of its ransomware profile: NIST IR 8374 Revision 1, now a CSF 2.0 Community Profile. It maps ransomware readiness to the CSF 2.0 outcomes across all six functions (including the newer “Govern” function).
If you have never used NIST before, do not get hung up on the word “profile.” Think of it like a sensible checklist of outcomes you can point your team, your IT provider, and your leadership group at.
A profile is useful because it forces one healthy conversation: what does “ready” mean for your business, specifically, and what are you willing to invest to reduce downtime?
The practical shift: more focus on decision-making and ownership
CSF 2.0 added a sixth function, Govern, and that change shows up clearly in the ransomware profile. In real life, ransomware is not only a technical problem. It is a business decision problem under time pressure.
Here is what “Govern” tends to mean for a growing business:
- Someone owns the risk. Not “IT” in general. A named role that can make calls when money, legal, and operations collide.
- Your expectations are written down. Things like MFA requirements, backup targets, and what has to be reported, and to whom.
- You have pre-decided the ugly choices. For example, who can approve shutting down systems, when you involve outside help, and how you will handle a ransom demand.
This is where many smaller companies get stuck. They buy tools, but they have not agreed on the decisions those tools are meant to support.
How to use the CSF 2.0 ransomware profile without turning it into a project
NIST’s CSF 2.0 guidance encourages using a Current Profile (what you actually do today) and a Target Profile (what you want to be able to say is true). The gap between them becomes your action plan.
Keep it lightweight:
- Pick a scope you can finish. For most businesses, start with Microsoft 365 identity, endpoints, and your backup and recovery process.
- Write your Current Profile honestly. “We think we have backups” is not a current state. “We can restore our file server in 6 hours, last tested in May” is.
- Choose a Target Profile that matches downtime reality. If one day of downtime costs you $50k, your target should look different than a business that can absorb a slow week.
If you do this well, you end up with fewer surprises and fewer debates during an incident.
The short list: controls that reduce downtime the most
There are many good controls in the NIST profile. If your goal is to reduce downtime, a few tend to do most of the work.
-
Identity hardening (especially admin accounts). Require MFA everywhere you can, and make it stronger for privileged access. Separate admin accounts from day-to-day accounts, and keep emergency “break glass” access tightly controlled. Ransomware crews love identity because it lets them spread fast and disable defences.
-
Backups that are isolated, and restores that are practiced. You already know you need backups. The downtime difference comes from isolation (so ransomware cannot wipe them) and from repeated restore drills (so you know the steps, timings, and missing dependencies). Test restores for the systems that actually run your business, not just a random folder.
-
A clear incident response “decision tree.” When ransomware hits, your team needs a simple flow: who declares an incident, who shuts down what, who talks to staff, who talks to customers, and who talks to legal or insurance. The goal is not paperwork. The goal is fewer minutes lost to confusion.
-
Logging and detection you can act on. You do not need a 24/7 security operations centre to benefit from basic detection. You do need alerts that somebody will see, and a plan for what happens when they do. If an alert cannot trigger a clear next step, it is mostly noise.
-
Patch the things attackers actually target. Prioritise internet-facing systems and known exploited vulnerabilities. This is one of the simplest ways to reduce the odds you ever need your recovery plan.
The part owners often miss: “recover” is a business process, not an IT task
Recovery is not only restoring data. It is restoring the business.
A good ransomware recovery plan answers questions like:
- What is the first service you bring back, and why? Email, line-of-business app, file access, phones, remote access, billing.
- What can your team do while systems are down? Manual workarounds, customer messaging, alternative devices, temporary processes.
- How will you decide whether to pay? NIST and CISA guidance consistently pushes organisations toward preparation and recovery without paying, and law enforcement discourages ransom payments. You still need a pre-agreed internal process for the decision, because the decision will land on your desk either way.
If you have never walked through those questions as a leadership team, that is your next best hour of ransomware work.
A simple next step you can do this week
If you want a practical starting point, do this in one meeting:
- Name an incident leader and a backup leader. Two names, two backups for each.
- Pick your top three “must restore” systems. The ones that keep revenue and operations moving.
- Schedule one restore test. Put it on the calendar, assign an owner, document the actual time and blockers.
- Write one page of incident decisions. Who can shut down systems, who contacts insurance, who contacts key customers, and how staff will be updated.
That is enough to turn “we hope we are ready” into “we are getting ready on purpose.”
Want a second set of eyes?
If you would like help turning the NIST ransomware profile into a short, realistic plan for your business, the Flexnet Networks team can help you scope it, prioritise the controls, and run the restore and response drills.
Sources
- IR 8374 Rev. 1, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile, NIST Computer Security Resource Center (CSRC)
- Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile (PDF), National Institute of Standards and Technology (NIST)
- NIST Cybersecurity Framework (CSF) 2.0 (PDF), National Institute of Standards and Technology (NIST)
- NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational Profiles (SP 1301) (PDF), National Institute of Standards and Technology (NIST)
- #StopRansomware Guide (September 2023), Cybersecurity and Infrastructure Security Agency (CISA)



